System with redundant central management controllers
A module to perform system management for a computer. The module includes a memory to store management event information and a controller to operate in an active central management controller mode and in a standby central management controller mode. In both modes the controller sends system event information to another controller to duplicate the management event information.
Latest Intel Patents:
- INTEGRITY-BASED IMPLEMENTATION OF CONTENT USING DIGITALLY SIGNED SECURE QUICK RESPONSE CODE
- ADAPTIVELY OPTIMIZING FUNCTION CALL PERFORMANCE
- REDISTRIBUTION LAYERS IN A DIELECTRIC CAVITY TO ENABLE AN EMBEDDED COMPONENT
- ENHANCEMENTS FOR ACCUMULATOR USAGE AND INSTRUCTION FORWARDING IN MATRIX MULTIPLY PIPELINE IN GRAPHICS ENVIRONMENT
- HOMOMORPHIC ENCRYPTION ENCODE/ENCRYPT AND DECRYPT/DECODE DEVICE
Embodiments of the present invention relate to system management. In particular, embodiments of the present invention relate to the topology and operation of system management controllers.
BACKGROUNDComputers and other electronic systems contains various components that may malfunction during the life of the system. In order to reduce and/or remedy such malfunctions, some systems include built-in features such as the ability to monitor and control the “health” or performance of the system hardware. Such features are sometimes referred to as system management, but also may be referred to by other names such as management, hardware management, platform management, etc. System management features may include, for example, the monitoring of elements such as temperatures, voltages, fans, power supplies, bus errors, system physical security, etc. In addition, system management features may also include determining information that helps identify a failed hardware component, and issuing an alert specifying that a component has failed.
One of the components that may be used to handle system management functions is a system management controller (also referred to herein as a “controller”). A system management controller may be a microprocessor, micro-controller, application specific integrated circuit (ASIC), or other type of processing unit that controls system management tasks. A system management controller may perform tasks such as receiving system management information, sending messages to control system performance, logging system management information, etc. For example, a system management controller may receive an indication from a temperature sensor that system temperature is rising, may send a command to increase fan speed, and may log the temperature reading.
One of the controllers in a system may perform the role of the central system management controller for that system, in which case it may perform central system management functions such as for example logging events, collecting field replaceable unit (FRU) inventory information, user interface, etc. The central management controller for a system may be referred to as the central management controller (CMC) or the baseboard management controller (BMC) for the system. It is common for a system to have only one active central management controller. Other non-central management controllers may be referred to as satellite management controllers (SMCs). An SMC may perform system management for a particular part or feature of a system. For example, a computer system may contain a number of circuit boards and other components that are connected by busses, with one board containing a central management controller for that system and other boards containing SMCs that performs other system management functions. In this example, the SMC's may send event information (e.g., a temperature reading) to the central management controller, while the central management controller may log event information and handle management requests (e.g., a request to change a temperature sensor threshold).
Embodiments of the present invention provide a system with a standby central management controller in addition to an active central management controller. The standby central management controller (“standby-CMC”) may monitor the active central management controller (“active-CMC”) and may takeover the role of active-CMC if the active-CMC has failed. In embodiments, the system has two or more controllers that support active and standby modes. Embodiments of the present invention provide for the mirroring of management information between cental management controllers and for the handling of management requests received at a standby-CMC.
Each module shown in system 100 contains a controller (113 and 123) and a computer readable medium (114 and 124). Each controller may be a processor that is capable of performing system management functions. Each computer readable medium may be any type of medium capable of storing instructions, such as a read only memory (ROM), a programable read only memory (PROM), or an erasable programable read only memory (EPROM). In an embodiment, the computer readable medium is a non-volatile memory. Each computer readable medium in
Each module is shown as including a memory (115 and 125) that is coupled to the controller on that module (113 and 123). Memory (115 and 125) maybe for example a volatile memory such as an SRAM, DRAM, etc., but may also be any other type of memory. In an embodiment, the memory (e.g., 115) that is associated with a controller (e.g., 113) may store management information that is used by the associated system management controller.
In an embodiment, the active-CMC instructions (e.g., 117) may be executed by a controller (e.g., 113) when that controller is in active-CMC mode and may perform active-CMC functions such as, for example, logging events, collecting field replaceable unit (FRU) inventory information, user interface, etc. In a further embodiment, the standby-CMC instructions (e.g., 128) may be executed by a controller (e.g., 123) when that controller is in standby-CMC mode to perform standby-CMC functions. For example, a standby-CMC may log a duplicate or mirror copy of the system management information stored in the memory that is associated with the active-CMC. In addition, a standby-CMC may monitor the active-CMC and, upon failure of the active-CMC, the standby-CMC may take over as the active-CMC. For example, controller 123 may be adapted to transition the controller 123 to active-CMC mode if the controller 113 is the active management controller for system 100 and the controller 123 determines that the controller 113 has failed.
According to embodiments of the invention, during operation, system 100 may have two-CMCs (113 and 123), one of which is an active-CMC and the other of which is a standby-CMC. Examples of such operation, including the mirroring of central management information and handling management requests by the standby-CMC, are discussed below with reference to
In the embodiment shown, controller 213 is the active-CMC for system 200 and controller 223 is the standby-CMC for system 200. In this embodiment, active-CMC 213 performs active-CMC functions for system 200 and standby system management controller 223 performs standby system management functions for system 200. Standby-CMC 223 may monitor active-CMC 213 and, if active-CMC 213 should fail, standby-CMC 223 may takeover the role of active-CMC for system 200.
System 200 is also shown as including a module 240 that has a satellite management controller (SMC) 241 and a sensor 246. In the embodiment shown, SMC 241 is coupled to system management bus 250, and sensor 246 is coupled to SMC 241. SMC 241 may be a controller, such as controllers 213 and 223, that performs satellite management controller functions. For example, module 240 may be a fan tray and sensor 246 may be a fan speed sensor, in which case SMC 241 may monitor the fan speed and send event information to a CMC in system 200. In other embodiments, module 240 may contain more or less sensors, and system 200 may contain more or less satellite management controllers, each of which may be on separate modules.
In an embodiment, the standby management controller may appear at the system management bus as a satellite management controller or, in a further embodiment, the controller may decline to send a response to a request at the system management bus (e.g., may not appear on the system management bus when in standby mode).
For purposes of illustration,
In an embodiment, the standby-CMC also monitors the active-CMC for failure, in which case the standby-CMC may take over as the active-CMC. In an embodiment, the monitoring is implemented by periodically pinging the active-CMC. For example, standby-CMC 223 may periodically (e.g., every 1000 ms) send a signal to active-CMC 213, and standby-CMC 223 may determine that active-CMC 213 has failed if standby-CMC has not received an acknowledgment within a threshold amount of time (e.g., 100 ms) of sending the signal. In another embodiment, the active-CMC periodically sends a signal to the standby CMC, and the standby-CMC determines that the active-CMC has failed if the standby-CMC has not received a signal as expected (i.e., the standby-CMC is a passive monitor). In embodiments, after the standby-CMC has determined that the active-CMC has failed, the standby-CMC takes over as the active CMC for the system. For example, the standby CMC may change its address on the system management bus 250 to the active address or notify SMCs to send events to the address of controller 223.
In another embodiment, the standby-CMC may send any management requests that it receives to the active-CMC be processed at the active-CMC. For example, standby-CMC 223 of
The active-CMC and standby-CMC may then continue to transmit event information between each other so that the SEL at each controller is current. As in the embodiment shown in
Embodiments of the present invention provide a subsystem that includes an active central management controller, which performs central system management functions, and a standby central management controller, which acts as a back-up in case of failure of the active central management controller. According to these embodiments, the system management functions will be reliably performed even when the active system management controller fails. Several embodiments of the present invention are specifically illustrated and/or described herein. However, it will be appreciated that modifications and variations of the present invention are covered by the above teachings and within the purview of the appended claims without departing from the spirit and intended scope of the invention. For example, the system management functions may be implemented as a hardware circuit or in software instructions and the order of execution of steps and instructions that are shown herein may be varied.
Claims
1. A machine-readable medium having stored thereon
- instructions to be executed by a standby central management controller in a computer, the instructions which, when executed, cause the standby central management controller to:
- receive a duplicate copy of management event information received from a first sensor from an active central management controller for the computer;
- store the duplicate copy of the management event information in a memory associated with the standby central management controller; and
- determine whether the active central management controller has failed and,
- if the active central management controller has failed:
- cause the standby central management controller to become the active central management controller for the computer; and
- receive event information from a second sensor in the memory associated with the stand-by central management controller now the active central management controller.
2. The machine-readable medium of claim 1, wherein the instructions further include instructions to:
- receive a management request;
- determine that the standby central management controller is not the active system management controller for the computer and, based on this determination, cause the standby central management controller to become the active central management controller for the computer; and
- process the management request after the standby central management controller has become the active central management controller.
3. The machine-readable medium of claim 1, wherein the instructions further include instructions to:
- receive a management request from a requestor;
- determine that the standby central management controller is not the active central management controller for the computer and, based on this determination, forward the management request to the active central management controller;
- receive an indication from the active central management controller that the management request has been processed; and
- send a response to the requestor.
4. The machine-readable medium of claim 1, wherein the instructions further include instructions to:
- receive information for an event that occurred locally with regard to the standby central management controller;
- store the event information in a local system event log of the standby central management controller; and
- forward the event information to the active central management controller.
5. The machine-readable medium of claim 4, wherein the system has a dedicated connection between the standby central management controller and the active central management controller, wherein the duplicate copy of management event information is received over the dedicated connection, and wherein the event information is forwarded to the active central management controller over the dedicated connection.
6. The machine-readable medium of claim 4, wherein the instructions determine that the active central management controller has failed if the standby central management controller has not received a signal from the active central management controller within a threshold amount of time.
7. The machine-readable medium of claim 1, wherein the instructions to determine if the active management controller has failed include instructions to:
- send a signal to the active central management controller; and
- determine that the active central management controller has failed if a response to the signal is not received from the active central management controller within a threshold response time.
8. The machine-readable medium of claim 1, wherein the instructions cause the standby controller to:
- receive a request over an Intelligent Platform Management Bus; and
- determine that a response to the request should not be sent because the recipient of the request is in standby central management controller mode.
9. A system comprising:
- an Intelligent Platform Management Bus;
- a first controller having a first sensor to detect an event requiring management control coupled to the Intelligent Platform Management Bus which contains firmware to support both an active central management controller mode and a standby central management controller mode; and
- a second controller having a second sensor to detect the event coupled to the Intelligent Platform Management Bus which contains firmware to support both an active central management controller mode and a standby central management controller mode, wherein the firmware in the first and second controllers support mirroring of event information between the first and second controllers.
10. The system of claim 9, wherein the firmware in the first controller causes the first controller to transition to active central management controller mode if the first controller is in standby central management controller mode and receives a management request, and wherein the firmware in the second controller causes the second controller to transition to active central management controller mode if the second controller is in standby central management controller mode and receives a management request.
11. The system of claim 9, wherein the firmware in the first controller causes a management request received at the first controller to be sent to the second controller if the first controller is in standby central management controller mode when it receives the management request, and wherein the firmware in the second controller causes a management request received at the second controller to be sent to the first controller if the second controller is in standby central management controller mode when it receives the management request.
12. The system of claim 9, wherein the system further comprises a dedicated connection between the first controller and the second controller.
13. The system of claim 9, wherein the firmware in the first controller causes the first controller to appear on the Intelligent Platform Management Bus as a satellite management controller if the first controller is in standby central management controller mode, and wherein the firmware in the second controller causes the second controller to appear on the Intelligent Platform Management Bus as a satellite management controller if the second controller is in standby central management controller mode.
14. The system as recited in claim 9, further comprising:
- a first circuit board including the first controller and the first sensor to be inserted into slots of a system board connecting to the Intelligent Platform Management Bus; and
- a second circuit board including the second controller and the second sensor to be inserted into slots of the system board connecting to the Intelligent Platform Management Bus.
15. The system as recited in claim 9, wherein the first sensor and the second sensor comprise temperature sensors to control a fan speed.
4521871 | June 4, 1985 | Galdun et al. |
4532594 | July 30, 1985 | Hosaka et al. |
5434998 | July 18, 1995 | Akai et al. |
5544077 | August 6, 1996 | Hershey |
5544304 | August 6, 1996 | Carlson et al. |
5796937 | August 18, 1998 | Kizuka |
5896492 | April 20, 1999 | Chong, Jr. |
6085333 | July 4, 2000 | DeKoning et al. |
6154850 | November 28, 2000 | Idleman et al. |
6275953 | August 14, 2001 | Vahalia et al. |
6327670 | December 4, 2001 | Hellenthal et al. |
6425092 | July 23, 2002 | Evans et al. |
6505272 | January 7, 2003 | Bouvier et al. |
6622265 | September 16, 2003 | Gavin |
6675268 | January 6, 2004 | DeKoning et al. |
20020144086 | October 3, 2002 | Tanaka et al. |
20020166020 | November 7, 2002 | Irving et al. |
20030014587 | January 16, 2003 | Bouvier et al. |
- Sun Microsystems, Presentation to the PICMG 2.13 Working Group, “Managed Redundant System Slot Operations”.
- Intel Corp., Hewlett-Packard Co., NEC Corp., Dell Computer Corp., “IPMI: Intelligent Platform Management Interface Specification”, v1.5, Document Revision 1.0, Chapters 1-3, pp. 1-29, Feb. 21, 2001.
- Intel Corp., product description: “Intel® NetStructure™ ZT 7101 Chassis Management Module”, 2001.
- Intel Corporation, Presentation to the PICMG Working Group, “Proposal for RASM Sub Team Consideration”, 2001.
- System Management Bus (SMBus) Specification, Version 2.0, SBS Implementers Forum, Aug. 3, 2000.
- “The I2C Faq”, The I2C Faq On-Line; http://www.ping.be/˜ping0751/i2cfaq/.
- U.S. Appl. No. 10/014,904, filed Dec. 14, 2001.
- U.S. Appl. No. 10/092,793, filed Mar. 8, 2002.
Type: Grant
Filed: Mar 12, 2002
Date of Patent: Sep 20, 2005
Patent Publication Number: 20030188051
Assignee: Intel Corporation (Santa Clara, CA)
Inventors: Peter A. Hawkins (San Luis Obispo, CA), Clyde S. Clark (Atascadero, CA)
Primary Examiner: Jeffrey Gaffin
Assistant Examiner: David Martinez
Attorney: Kevin A. Reif
Application Number: 10/094,629